Results 1 to 5 of 5
  1. #1
    Join Date
    Oct 2012
    Posts
    282
    Plugin Contributions
    0

    Default My Client want to take Credit Card info themselves. Is there a module...?

    I know this is a crazy request and goes against everything i've learned about e-commerce, internet security etc. etc. but my client wants complete access to customers credit card numbers. i.e., be able to store and retrieve via their ZenCart DB. that is currently how they are operating with their ShopSite website.

    I won't go into too much detail but my client's customer orders are highly customize, personalized. so much so that once received order details are not completed until a phone call takes place. after which the credit card is then processed.

    any recommendations on how i could implement this on ZenCart? is there a plugin that could facilitate this? crazy i know but i have to ask

  2. #2
    Join Date
    Feb 2005
    Location
    Lansing, Michigan USA
    Posts
    20,024
    Plugin Contributions
    3

    Default Re: My Client want to take Credit Card info themselves. Is there a module...?

    There's no provision for storing credit card details in the Zencart database, nor any mod that will do that which I'm aware of. My suggestion, for what it's worth, would be to distance yourself from this client ASAP.

  3. #3
    Join Date
    Jan 2004
    Posts
    66,364
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: My Client want to take Credit Card info themselves. Is there a module...?

    Or, explore getting them trained to have their store only "authorize" the payment, and not actually "capture" the payment. They'd have to manually capture the payment at the time the order is finalized. But if the amount will always be changing to something different than what they did online, then chances are they should be building something to have the customer pay the final amount at the time the amount is determined, not up-front as your description implies right now. That's just for the basic legalities of not charging until the amount is determined and fulfillment is starting to occur (ie: shipping the product).
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    6,167
    Plugin Contributions
    7

    Default Re: My Client want to take Credit Card info themselves. Is there a module...?

    Quote Originally Posted by tcarden View Post
    I know this is a crazy request and goes against everything i've learned about e-commerce, internet security etc. etc. but my client wants complete access to customers credit card numbers. i.e.,
    Actually it isn't quite as crazy as you may think. There are actually a number of benefits to be had from this, especially for merchants that already have their own CC facilities. Furthermore, an argument could be made that this can actually be more secure than using a gateway/payment processor..... but ..........................

    Quote Originally Posted by tcarden View Post
    be able to store and retrieve via their ZenCart DB. that is currently how they are operating with their ShopSite website.
    ............ Unless the CC information is stored in an encrypted format they are running a high risk of running foul with their merchant agreement and stand to lose their merchant account.

    Quote Originally Posted by tcarden View Post
    I won't go into too much detail but my client's customer orders are highly customize, personalized. so much so that once received order details are not completed until a phone call takes place. after which the credit card is then processed.

    any recommendations on how i could implement this on ZenCart? is there a plugin that could facilitate this? crazy i know but i have to ask
    At one time there was a module for ZenCart to process Credit cards directly, but due to PCI requirements I don't think this is supported any longer. It may or may not still be available in the add-ons section. If it is it probably isn't PCI compliant anyway so I'd be reluctant to recommend its use.

    Now having said that, and based on the fact that the client doesn't process the orders until a phone call takes place anyway, my suggestion would be to use a 'pay by phone' module so that the CC details are retrieved and processed entirely offline. It would be illegal for the client to store these details (unencrypted) on the same host/server as ZenCart itself. so if they really *must* keep a copy of this information they should do so on their local computer only.

    ZenCart *can* be made to handle CC's in a way that doesn't run afoul of the PCI requirements (which are really just a set of rules of 'good security practices' anyway) but it can only take things 'so far'. There are many PCI requirements that cannot be enforced by ZenCart itself, so those that insist on going this way need to also familiarise themselves with *all* the PCI requirements, and not falling into the trap of thinking that SSL and encryption is the end of the matter.

    Cheers
    RodG

  5. #5
    Join Date
    Oct 2012
    Posts
    282
    Plugin Contributions
    0

    Default Re: My Client want to take Credit Card info themselves. Is there a module...?

    thanks for feedback, much appreciated!

 

 

Similar Threads

  1. v151 client doesn't want credit card processing but wants the #
    By KaySharpe in forum General Questions
    Replies: 2
    Last Post: 15 May 2013, 12:20 PM
  2. Is there a most basic Payment module to just collect credit card number?
    By BigDiscounts in forum Addon Payment Modules
    Replies: 3
    Last Post: 27 Jun 2011, 12:38 AM
  3. Replies: 1
    Last Post: 26 Oct 2009, 03:30 AM
  4. I don't want Credit Card info entered directly on my site
    By dableys in forum General Questions
    Replies: 13
    Last Post: 10 Aug 2008, 04:02 PM
  5. Replies: 0
    Last Post: 12 Mar 2008, 02:14 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR